#offseq

125 posts · Last used 4h

Back to Timeline
OffSequence @offseq@infosec.exchange · 4h ago
SSRF in mf-yang openclaw-cn (CVE-2026-17458) affects v0.2.0 & v0.2.1. MEDIUM severity, CVSS 5.3. Exploit details public, no patch yet. Restrict outbound server requests as interim mitigation. https://radar.offseq.com/threat/cve-2026-17458-server-side-request-forgery-in-mf-yang-openclaw-cn-a8d78509307a6c7f #OffSeq #SSRF #Vuln #mfyang
0
0
0
OffSequence @offseq@infosec.exchange · 9h ago
'preferenceslifecycle-paypal' npm v28.0.0 marked HIGH severity for malicious behavior — communicates with a malicious domain. No CVE, no known exploits yet. Remove or avoid usage until official guidance. https://radar.offseq.com/threat/malicious-code-in-preferenceslifecycle-paypal-npm-9a765312fd726ca7 #OffSeq #npm #ThreatIntel #Infosec
0
0
0
OffSequence @offseq@infosec.exchange · 12h ago
'f0-form-manipulator' v28.0.0 (npm) flagged as malicious (HIGH) by OpenSSF. Package communicates with a known bad domain — no CVE or CVSS, no exploits yet. Remove or avoid this version. Monitor advisories for updates. https://radar.offseq.com/threat/malicious-code-in-f0-form-manipulator-npm-fe8afbba3f39b359 #OffSeq #npm #infosec #SupplyChain
0
0
0
OffSequence @offseq@infosec.exchange · 13h ago
xo-member-components v28.0.0 (npm) flagged as malicious (HIGH severity): connects to a known malicious domain. No patch exists — remove or avoid this version. No active exploits reported. https://radar.offseq.com/threat/malicious-code-in-xo-member-components-npm-19227206998cf01d #OffSeq #npm #SupplyChain #Infosec
0
0
0
OffSequence @offseq@infosec.exchange · 15h ago
Malicious behavior found in npm 'identityscimapiserv' v28.0.0 🛑 Severity: HIGH. Package communicates with a domain tied to malicious activity. Remove if used; no patch yet. Monitor advisories. No CVE assigned. https://radar.offseq.com/threat/malicious-code-in-identityscimapiserv-npm-a93956087670de52 #OffSeq #npm #infosec #threatintel
0
0
0
OffSequence @offseq@infosec.exchange · 1d ago
CVE-2026-10818: WPForms Pro <=1.10.1.1 has a HIGH severity file upload vuln (CVSS 8.1). Unauthenticated RCE possible via ajax_chunk_upload_finalize. Restrict access & monitor uploads until a patch is released. https://radar.offseq.com/threat/cve-2026-10818-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-wpforms-wpforms-pro-98bc8d14f7da8c03 #OffSeq #WordPress #Infosec #CVE202610818
0
0
0
OffSequence @offseq@infosec.exchange · 1d ago
Microsoft Purview Data Governance is impacted by CVE-2026-57106 (SSRF, CVSS 10, CRITICAL). Remote attackers can escalate privileges — patch ASAP using the official fix: https://radar.offseq.com/threat/cve-2026-57106-cwe-918-server-side-request-forgery-ssrf-in-microsoft-microsoft-purview-data-governance-0983080847f54f67 #OffSeq #Vuln #SSRF #Microsoft #CyberSec
0
0
0
OffSequence @offseq@infosec.exchange · 1d ago
CVE-2026-58630: Improper access control in Azure App Service for Linux (CVSS 10, CRITICAL) lets remote attackers escalate privileges with no auth or user action. Patched by Microsoft — verify updates. Details: https://radar.offseq.com/threat/cve-2026-58630-cwe-284-improper-access-control-in-microsoft-azure-app-service-for-linux-12c1219307778a3e #OffSeq #Azure #Infosec #CVE2026_58630
0
0
0
OffSequence @offseq@infosec.exchange · 1d ago
CVE-2026-56163: CRITICAL (CVSS 10) in Azure Kubernetes Service — Missing authentication allows remote privilege escalation. Microsoft has released a fix; verify your AKS is updated. https://radar.offseq.com/threat/cve-2026-56163-cwe-306-missing-authentication-for-critical-function-in-microsoft-azure-kubernetes-c5571c5da7b404e3 #OffSeq #Azure #Kubernetes #CloudSecurity
0
0
0
OffSequence @offseq@infosec.exchange · 1d ago
CVE-2026-62835 (CRITICAL, CVSS 9.3) affects Microsoft Azure Portal: improper authorization enables remote info disclosure with high confidentiality impact. Microsoft has fixed server-side. More at https://radar.offseq.com/threat/cve-2026-62835-cwe-285-improper-authorization-in-microsoft-azure-portal-defd11bbcf2e17c7 #OffSeq #Azure #Vuln #CloudSecurity
0
0
0
OffSequence @offseq@infosec.exchange · 2d ago
CRITICAL improper authorization vuln (CVE-2026-56160) in Azure Red Hat OpenShift (ARO): privilege escalation risk for authorized users. No active exploits. Microsoft has released a fix — ensure your ARO instances are updated. Details: https://radar.offseq.com/threat/cve-2026-56160-cwe-285-improper-authorization-in-microsoft-azure-red-hat-openshift-aro-9a561de9f992bb49 #OffSeq #Azure #CVE202656160
0
0
0
OffSequence @offseq@infosec.exchange · 2d ago
CVE-2026-24727 (CRITICAL, CVSS 9.3): SUNNET Corporate Training Mgmt System v10.3 allows admins to upload ZIP files with executable code, enabling server command execution. No patch yet — restrict admin access & monitor uploads. https://radar.offseq.com/threat/cve-2026-24727-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-sunnet-technology-co-ltd-fe23deeb060f5b6d #OffSeq #CVE202624727 #infosec 🛡️
0
0
0
OffSequence @offseq@infosec.exchange · 2d ago
CVE-2026-12981: CRITICAL vuln in CAFEHAUS API plugin ≤1.0.0 (WordPress). No authentication on password updates — attackers can reset any user password, including admins. Remove/disable plugin until fixed. https://radar.offseq.com/threat/cve-2026-12981-cwe-269-improper-privilege-management-in-cafehaus-api-47b92cb62ac9c312 #OffSeq #WordPress #Vulnerability #PrivilegeEscalation
0
0
0
OffSequence @offseq@infosec.exchange · 2d ago
CVE-2026-50517: CRITICAL deserialization flaw (CVSS 9.9) in Microsoft 365 Copilot permits remote code execution by authorized attackers. Microsoft has issued a server-side fix — confirm your environment is protected. https://radar.offseq.com/threat/cve-2026-50517-cwe-502-deserialization-of-untrusted-data-in-microsoft-microsoft-365-copilot-71d778a5726cf6f5 #OffSeq #Microsoft365 #CloudSecurity #CVE202650517
0
0
0
OffSequence @offseq@infosec.exchange · 2d ago
CVE-2026-56191: CRITICAL improper authentication in Microsoft Exchange Online (CVSS 10). Remote, unauthenticated attackers can tamper with systems. Official fix available — patch ASAP. Details: https://radar.offseq.com/threat/cve-2026-56191-cwe-287-improper-authentication-in-microsoft-microsoft-exchange-online-2fb5560625ca8222 #OffSeq #CVE202656191 #ExchangeOnline #Vuln
0
1
0
OffSequence @offseq@infosec.exchange · 2d ago
CVE-2026-58275 | Microsoft Azure DNS (CRITICAL, CVSS 10): Missing authorization lets attackers escalate privileges remotely — integrity & availability at risk. Microsoft has patched server-side. Details: https://radar.offseq.com/threat/cve-2026-58275-cwe-862-missing-authorization-in-microsoft-azure-dns-8fa245e6deabe29a #OffSeq #Azure #CVE #CloudSecurity
0
0
0
OffSequence @offseq@infosec.exchange · 2d ago
CVE-2026-42933: CRITICAL unintended proxy vuln (CVSS 10) in Pronetiqs Panduit Intravue ≤3.2.1a14 lets attackers bypass OT segmentation. No patch yet — restrict access & monitor vendor. https://radar.offseq.com/threat/cve-2026-42933-cwe-441-unintended-proxy-or-intermediary-confused-deputy-in-pronetiqs-panduit-intravue-95925181c2d7dbb4 #OffSeq #OTSecurity #Vuln #CVE202642933
0
0
0
OffSequence @offseq@infosec.exchange · 3d ago
CVE-2026-65907: CRITICAL RCE in JetBrains TeamCity (CVSS 9.1). Affects <2026.1.2, <2025.11.6. Exploitable via Git VCS roots — no patch yet. Restrict access, minimize Git user privileges. More info: https://radar.offseq.com/threat/cve-2026-65907-cwe-94-in-jetbrains-teamcity-0b7d157127b512e7 #OffSeq #TeamCity #Vuln #RCE
0
0
0
OffSequence @offseq@infosec.exchange · 3d ago
CVE-2026-16723: CRITICAL RCE in Alibaba Fastjson 1.2.68. Exploitable under default config — no patch yet. Avoid 1.2.68 & monitor vendor updates for mitigation. CVSS 9.0. https://radar.offseq.com/threat/cve-2026-16723-cwe-20-improper-input-validation-in-alibaba-fastjson-939ed165aac7ce81 #OffSeq #infosec #CVE202616723 #remotecodeexecution
0
0
0
OffSequence @offseq@infosec.exchange · 3d ago
'caldryn' npm package found with malicious code (CRITICAL). Full system compromise possible — attackers may persist after removal. Rotate all secrets/keys from a secure environment and investigate for persistence. https://radar.offseq.com/threat/malicious-code-in-caldryn-npm-b4e3f61925b758b5 #OffSeq #npm #SupplyChain #Infosec
0
0
0